mirror of
https://github.com/Alfresco/alfresco-ng2-components.git
synced 2026-09-09 18:03:21 +00:00
AAE-48307 Fix: rebase silentRefreshRedirectUri onto the current window origin to prevent cross-domain logout
This commit is contained in:
@@ -167,6 +167,38 @@ describe('AuthConfigService', () => {
|
|||||||
spyOnProperty(appConfigService, 'oauth2').and.returnValue(mockAuthConfigSubfolder2RedirectUri);
|
spyOnProperty(appConfigService, 'oauth2').and.returnValue(mockAuthConfigSubfolder2RedirectUri);
|
||||||
expect(service.loadAppConfig().silentRefreshRedirectUri).toBe(expectedUri);
|
expect(service.loadAppConfig().silentRefreshRedirectUri).toBe(expectedUri);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('should rebase the silentRefreshRedirectUri onto the current window origin when the configured domain differs', () => {
|
||||||
|
spyOnProperty(appConfigService, 'oauth2').and.returnValue({
|
||||||
|
...mockAuthConfigImplicitFlow,
|
||||||
|
redirectSilentIframeUri: 'https://different-domain.com/assets/silent-refresh.html'
|
||||||
|
});
|
||||||
|
expect(service.loadAppConfig().silentRefreshRedirectUri).toBe('http://localhost:3000/assets/silent-refresh.html');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('should preserve the subfolder path while rebasing onto the current window origin', () => {
|
||||||
|
spyOnProperty(appConfigService, 'oauth2').and.returnValue({
|
||||||
|
...mockAuthConfigImplicitFlow,
|
||||||
|
redirectSilentIframeUri: 'https://different-domain.com/subfolder/assets/silent-refresh.html'
|
||||||
|
});
|
||||||
|
expect(service.loadAppConfig().silentRefreshRedirectUri).toBe('http://localhost:3000/subfolder/assets/silent-refresh.html');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('should resolve a relative silentRefreshRedirectUri against the current window origin', () => {
|
||||||
|
spyOnProperty(appConfigService, 'oauth2').and.returnValue({
|
||||||
|
...mockAuthConfigImplicitFlow,
|
||||||
|
redirectSilentIframeUri: '/assets/silent-refresh.html'
|
||||||
|
});
|
||||||
|
expect(service.loadAppConfig().silentRefreshRedirectUri).toBe('http://localhost:3000/assets/silent-refresh.html');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('should return the configured value unchanged when redirectSilentIframeUri is not set', () => {
|
||||||
|
spyOnProperty(appConfigService, 'oauth2').and.returnValue({
|
||||||
|
...mockAuthConfigImplicitFlow,
|
||||||
|
redirectSilentIframeUri: undefined
|
||||||
|
});
|
||||||
|
expect(service.loadAppConfig().silentRefreshRedirectUri).toBeUndefined();
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe('postLogoutRedirectUri', () => {
|
describe('postLogoutRedirectUri', () => {
|
||||||
|
|||||||
@@ -63,7 +63,7 @@ export class AuthConfigService {
|
|||||||
issuer: oauth2.host,
|
issuer: oauth2.host,
|
||||||
nonceStateSeparator: '~',
|
nonceStateSeparator: '~',
|
||||||
redirectUri,
|
redirectUri,
|
||||||
silentRefreshRedirectUri: oauth2.redirectSilentIframeUri,
|
silentRefreshRedirectUri: this.getSilentRefreshRedirectUri(),
|
||||||
postLogoutRedirectUri: this.generatePostLogoutUri(origin, oauth2.redirectUriLogout),
|
postLogoutRedirectUri: this.generatePostLogoutUri(origin, oauth2.redirectUriLogout),
|
||||||
clientId: oauth2.clientId,
|
clientId: oauth2.clientId,
|
||||||
scope: oauth2.scope,
|
scope: oauth2.scope,
|
||||||
@@ -106,6 +106,17 @@ export class AuthConfigService {
|
|||||||
return (oauth2.codeFlow || oauth2.implicitFlow) && useHash ? `${redirectUri}/?` : redirectUri;
|
return (oauth2.codeFlow || oauth2.implicitFlow) && useHash ? `${redirectUri}/?` : redirectUri;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private getSilentRefreshRedirectUri(): string | undefined {
|
||||||
|
const uri = this.appConfigService.oauth2.redirectSilentIframeUri;
|
||||||
|
const origin = this.getLocationOrigin();
|
||||||
|
try {
|
||||||
|
const { pathname, search, hash } = new URL(uri || origin, origin);
|
||||||
|
return uri ? `${origin}${pathname}${search}${hash}` : uri;
|
||||||
|
} catch {
|
||||||
|
return uri;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
private getLocationOrigin() {
|
private getLocationOrigin() {
|
||||||
return window.location.origin;
|
return window.location.origin;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user